SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-44090

CRITICAL · CVSS 9.8 EPSS 0.43%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated remote attackers to access the MQTT broker, potentially leading to full device compromise, as it relies solely on firewall protection for external access. Organizations utilizing MQTT brokers in their infrastructure should prioritize addressing this critical issue to prevent unauthorized access and potential exploitation. Immediate action is recommended for those managing IoT devices or systems that depend on MQTT for communication.

CVE
CVE-2026-44090
Severity
CRITICAL
CVSS
9.8
EPSS
0.43%

Original NVD Description

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.